Certificate Authority Selection in Cloud Provider Networks
Through Certificate Management Service (CMS) automatic selection of certificate agencies (CAs) based on policies, it solves the problem that users find it difficult to choose the right CA in the cloud environment, and improves the efficiency and accuracy of certificate issuance.
Patent Information
- Application Number
- CN202380029138.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-03-21
- Filing Date
- 2023-03-14
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-03-14
AI Technical Summary
In modern cloud-based environments, it is difficult for users to effectively choose the right certificate agency (CA) to issue certificates, resulting in incorrect certificate issuance and increased management burden, reducing the efficiency of certificate issuance.
The CA selection policy is implemented through Certificate Management Service (CMS). Based on the policy rules of user identity, role or group, the appropriate CA is automatically selected to process certificate requests, reducing human errors and improving the speed of certificate issuance.
It simplifies the certificate issuance process, improves the efficiency of certificate issuance, reduces errors, reduces user management burden, and enhances the accuracy of certificate selection.
Smart Images

Figure CN119054251B_ABST
Abstract
Description
Background Art
[0001] A certificate refers to a digital document that has been encrypted for protection and enables secure communication. Certificates are typically used in a cryptographic system known as Public Key Infrastructure (PKI). PKI relies on an asymmetric encryption system using key pairs (private keys and public keys) to encrypt and decrypt data, digitally sign data, etc. A public key can be associated with a digital certificate that attests to the owner of the given public key. Digital certificates are created and signed by a public or private certificate authority acting as a trusted third party. A typical use case for certificates is to secure network communication via Secure Sockets Layer (SSL) / Transport Layer Security (TLS), although certificates can also be used for other security purposes, such as digitally signing files to ensure they originate from the holder of the certificate. Certificates can be referred to as X.509 certificates (referring to the industry standard for certificate systems). Brief Description of the Drawings
[0002] Various embodiments in accordance with the present disclosure will be described with reference to the accompanying drawings, in which:
[0003] Figure 1 is a diagram showing an environment for certificate authority selection according to some embodiments.
[0004] Figure 2 is a diagram showing an environment for configuring a certificate authority selection policy according to some embodiments.
[0005] Figure 3 is a diagram showing an exemplary certificate authority selection policy according to some embodiments.
[0006] Figure 4 is a diagram showing an environment in which different certificate authorities are selected according to some embodiments.
[0007] Figure 5 is a flowchart showing the operations of a method for certificate authority selection according to some embodiments.
[0008] Figure 6 shows an exemplary provider network environment that can be used in some embodiments.
[0009] Figure 7 is a block diagram of an exemplary provider network that provides storage services and hardware virtualization services to customers according to some embodiments.
[0010] Figure 8 is a block diagram showing an example computer system that can be used in some embodiments. Detailed Description
[0011] The present disclosure relates to a method, apparatus, system, and non-transitory computer-readable storage medium for CA selection from multiple certificate authorities (CAs) when processing certificate-related requests. For example, a Certificate Management Service (CMS) may select an appropriate CA for a certificate creation request (sometimes referred to as "issuing" a certificate). The CMS may be configured with one or more policies that govern the selection of the CA based on one or more parameters indicated in the request. Upon receiving a request from a requester (e.g., a user), the CMS may identify one or more policies applicable to the request and then evaluate the one or more policies to determine which CA to use to satisfy the request.
[0012] In modern cloud-based environments, there may be multiple CAs and the multiple CAs provide different services. Some CAs may issue public certificates (e.g., for use in securing communications traversing a public network such as the Internet or communications with entities outside of a user's organization), while other CAs may issue private certificates (e.g., for use in securing communications between intra-cloud hosted resources within an organization or between associated users on a private network). Users generally do not know which CA to direct their certificate-related requests to. For example, when requesting a new certificate, users generally do not know from which CA the certificate must be issued and may inadvertently obtain a certificate from the wrong CA. To address these challenges, in particular, the CMS CA selection described herein simplifies the process of a user's certificate-related requests in a cloud-based environment. Among other benefits, the CMS CA selection also increases the speed at which users can obtain new certificates, reduces errors in the issuance of certificates, and alleviates the administrative burden of communicating to users the appropriate CA for a particular certificate request or a particular type of certificate request.
[0013] Figure 1FIG. is a diagram showing an environment for certificate authority selection according to some embodiments. Provider network 100 (or "cloud" provider network) provides users with the ability to use one or more of various types of computing-related resources, such as computing resources (e.g., executing virtual machine (VM) instances and / or containers, executing batch jobs, executing code without pre-configuring a server), data / storage resources (e.g., object storage, block-level storage, data archive storage, databases and database tables, etc.), network-related resources (e.g., configuring virtual networks (including multiple sets of computing resources), content delivery networks (CDN), domain name services (DNS)), application resources (e.g., databases, application build / deployment services), access policies or roles, identity policies or roles, machine images, routers, and other data processing resources, etc. These and other computing resources may be provided as services, such as: a hardware virtualization service for executable computing instances, a storage service for storing data objects, etc. Users of provider network 100 (or "customers") may use one or more user accounts associated with a customer account, but these items may be used somewhat interchangeably depending on the usage context. Users may interact with provider network 100 via one or more interfaces 108 across one or more intermediate networks 104 (e.g., the Internet), such as by using application programming interface (API) calls, via a console implemented as a website or application, etc. An API refers to an interface and / or communication protocol between a client and a server such that if a client issues a request in a predefined format, the client should receive a response in a specific format or initiate a defined action. In the cloud provider network scenario, the API provides a gateway for customers to access the cloud infrastructure by allowing them to obtain data from or cause actions within the cloud provider network, thereby enabling the development of applications that interact with the resources and services hosted in the cloud provider network. The API may also enable different services of the cloud provider network to exchange data with each other. Interface 108 may be part of or act as a front-end to the control plane of provider network 100, which includes "backend" services that support and implement services that can be provided more directly to customers.
[0014] For example, a cloud provider network (or simply referred to as "cloud") generally refers to a large pool of accessible virtualized computing resources, such as computing, storage, and networking resources, applications, and services. The cloud can provide convenient, on-demand network access to a shared pool of configurable computing resources that can be programmatically provisioned and released in response to customer commands. These resources can be dynamically provisioned and reconfigured to adjust to variable loads. Thus, cloud computing can be considered as both applications delivered as a service via a publicly accessible network (e.g., the Internet, cellular communication network) and the hardware and software in the cloud provider data centers that provide these services.
[0015] A cloud provider network can be formed into multiple regions, where a region is a geographical area in which the cloud provider aggregates data centers. Each region includes multiple (e.g., two or more) Availability Zones (AZs) connected to each other via a private high-speed network (e.g., fiber optic communication link). An AZ (also referred to as a "zone") provides an isolated failure domain that includes one or more data center facilities, and the one or more data center facilities have separate power, separate networking, and separate cooling relative to the data center facilities in another AZ. A data center refers to a physical building or enclosure that houses the servers of the cloud provider network and provides power and cooling to the servers of the cloud provider network. Preferably, the AZs within a region are located far enough apart from each other such that a natural disaster (or other failure-causing event) does not affect more than one AZ or take more than one AZ offline at the same time.
[0016] A user can connect to an AZ of the cloud provider network via a publicly accessible network (e.g., the Internet, a cellular communication network), such as through a Transit Center (TC). The TC is the main backbone location that links the user to the cloud provider network and can be co-located at other network provider facilities (e.g., an Internet Service Provider (ISP), a telecommunications provider) and securely connected to the AZ (e.g., via a VPN or a direct connection). Each region can operate two or more TCs to achieve redundancy. The regions are connected to a global network, which includes private networking infrastructure (e.g., fiber optic connections controlled by the cloud provider) that connects each region to at least one other region. The cloud provider network can deliver content from edge locations and regional edge cache servers from Points of Presence (or "POPs") located outside but networked with these regions. This partitioning and geographical distribution of computing hardware enables the cloud provider network to provide low-latency resource access to users globally with a high degree of fault tolerance and stability.
[0017] Generally speaking, the operations and business of a provider network can be broadly divided into two categories: control plane operations carried on the logical control plane and data plane operations carried on the logical data plane. The data plane represents the movement of user data through a distributed computing system, while the control plane represents the movement of control signals through a distributed computing system. The control plane typically includes one or more control plane components that are distributed across and implemented by one or more control servers. Control plane operations typically include administrative operations such as system configuration and management (e.g., resource placement, hardware capacity management, diagnostic monitoring, system status information). The data plane includes user resources implemented on the provider network (e.g., computing instances, containers, block storage volumes, databases, file storage). Data plane operations typically include non-administrative operations such as delivering user data to and from user resources. Control plane components are typically implemented on a separate set of servers from the data plane servers, and control plane operations and data plane operations can be sent over separate / distinct networks.
[0018] To provide these and other computing resource services, provider network 100 typically relies on virtualization technologies. For example, virtualization technologies can provide users with the ability to control or use computing resources (e.g., "computing instances" such as VMs using a guest operating system (O / S), where the guest operating system operates using a hypervisor that may or may not further operate on top of the underlying host O / S; containers that may or may not operate within a VM; computing instances that can execute on "bare metal" hardware without an underlying hypervisor), where one or more computing resources can be implemented using a single electronic device. Thus, users can directly use the computing resources hosted by the provider network (e.g., provided by a hardware virtualization service) to perform various computing tasks. Additionally or alternatively, users can indirectly use computing resources by submitting code to be executed by the provider network (e.g., via an on-demand code execution service), and the provider network then uses one or more computing resources to execute the code, typically without the user having any control over or knowledge of the underlying computing instances involved.
[0019] As discussed above and as now Figure 1As shown, the embodiments disclosed herein include a Certificate Management Service (CMS) 114 of a provider network 100 that selects an appropriate CA for a certificate request. As shown, multiple CA services that can issue certificates are available. In particular, CAs 112A through 112N include CA 112A outside the provider network 100 and CAs 112B through 112N inside the provider network 100. The CAs 112 can be public or private CAs. Public CAs issue certificates that are typically used on a publicly accessible network (e.g., the Internet), while private CAs issue certificates that are used in a private network (e.g., a private corporate intranet). Additionally, the CAs 112 can be services of a cloud provider, services of a third party between the cloud provider and the user requesting the certificate, or services set up and configured by an administrator of an organization that includes the user requesting the certificate.
[0020] A user can use the CMS 114 to create and manage certificate-related resources. Various request types include certificate creation, certificate update, and certificate deletion. At least in the case of certificate creation and update, since a particular request may invoke one of multiple CAs, the CMS can act as an interface to the CAs by receiving the request and selecting an appropriate CA to process the request. To assist in CA selection, the CMS can be configured with one or more policies that govern the selection of a CA based on one or more parameters indicated in the request. When receiving a request from a requester (e.g., a user), the CMS can identify one or more policies applicable to the request and then evaluate the one or more policies to determine which CA to use to satisfy the request.
[0021] CA selection policies include one or more CA selection rules to be applied to certificate-related requests. CA selection policies can be associated with users, roles, user groups, etc. Refer to Figure 3 Exemplary CA selection policies are shown and described. At a higher level, the CMS 114 uses the CA selection policies to identify an appropriate CA based on one or more parameters included in a certificate-related request. As shown, the CMS 114 has multiple CA selection policies 118A through 118N in the CA selection policy data 116. The CA selection policy data 116 can be stored and accessed by the CMS 114 using a data repository (not shown). An exemplary data storage device is a virtual data repository provided by a virtualized data storage service such as described elsewhere herein.
[0022] In addition to handling the selection of CAs, the CMS 114 can provide many other features related to creating, storing, and updating public and private certificates (e.g., SSL / TLS X.509 certificates) and keys for protecting a user's websites and applications. Certificates created via the CMS 114 can protect a single domain name, multiple specific domain names, a wildcard domain, or a combination thereof. A user can also export the certificates signed by a private certificate authority managed by the CMS 114 for use anywhere within the user's internal PKI.
[0023] As indicated above, SSL / TLS certificates allow web browsers and other applications to identify websites and establish encrypted network connections with the websites using the SSL / TLS protocol. Certificates are used in a cryptosystem known as the public key infrastructure (PKI). PKI provides a way for one party to use a certificate to confirm the identity of another party (if both parties trust a third party), where the third party is called a certificate authority.
[0024] In some embodiments, the CMS 114 provides at least two different options for users desiring to deploy managed certificate-related resources. For example, the CMS 114 can provide a public certificate management service for users who need a secure web presence using TLS. In some embodiments, certificate-related resources created by the CMS 114 can be deployed to user resources via other services provided by a cloud provider (e.g., via a load balancing service, a content delivery network (CDN) service, an API gateway service, or other services where the user may have deployed endpoint resources), or otherwise returned to the requesting user. The CMS 114 can also provide a feature for implementing automatic renewal of expired certificates.
[0025] In some embodiments, the CMS 114 also provides a private certificate authority service. For example, the private certificate authority service can be used for private use within an organization. When establishing a secure encrypted communication channel, each endpoint uses a certificate and cryptographic techniques to prove its identity to the other endpoint. Internal API endpoints, web servers, VPN users, IoT devices, and many other applications use private certificates to establish the encrypted communication channels required for their secure operation. A user can create its own certificate authority (CA) hierarchy and use it to issue certificates for authenticating users, computers, applications, services, and other devices.
[0026] In some embodiments, the certificate-related resources managed by CMS114 are associated with a number of features. For example, in some embodiments, the certificates issued by CMS114 are domain-verified. The subject field of the certificate issued by CMS114 identifies the domain name, so when a user requests a certificate, the user verifies the ownership or control of all domains specified in the request. The ownership or control of the specified domain name can be verified by using email, DNS, or other methods supported by CMS114.
[0027] In some embodiments, the certificates issued by CA 112 can be associated with a defined validity period (e.g., 13 months or any other time period). CMS114 can also manage the process of renewing the certificate and pre-configuring the certificate after the certificate is renewed. In some embodiments, the certificates issued by CA 112 are trusted by mainstream browsers (Google Chrome, Microsoft Internet Explorer and Microsoft Edge, Mozilla Firefox, etc.) and operating systems.
[0028] In some embodiments, each CMS114 certificate includes at least one fully qualified domain name (FQDN), and the user can add additional names as needed. For example, a user who creates a certificate for www.example.com can also add the name www.example.net (if the user accesses the site using either name). CMS114 also allows the user to use an asterisk (*) in the domain name to create a certificate with a wildcard name, which can protect several sites in the same domain. For example, *.example.com protects www.example.com and images.example.com. In some embodiments, the certificate also specifies the algorithm and key length. CMS114 can support, for example, a number of public key algorithms, including but not limited to: 2048-bit RSA, 4096-bit RSA, 256-bit Elliptic Prime Curve, 384-bit Elliptic Prime Curve, etc. The certificate can be associated with other parameters as described herein.
[0029] As described above, one of the requests related to certificates is the creation (or issuance) of a new certificate. Now, with reference to the circled numbers 1 to 5, an exemplary set of operations related to the creation of certificates by CMS114 will be described.
[0030] At circle “1”, a user of the electronic device 102A sends a request 126 for a new certificate to the CMS 114 using an API, web-based console, CLI, or other interface provided by the CMS 114. The request typically includes an indication of the user's identity (or role) and an identification of the domain name associated with the requested certificate. The indication of the user's identity can be a security token or other credential obtained by the user when authenticating to the provider network 100. The domain name can be a fully qualified domain name, subdomain, wildcard domain, etc. (e.g., *.example.com, images.example.com, *.blog.example.com, etc.). In some embodiments, the domain name is some other indication of the identity of the entity that will use the certificate to secure communications.
[0031] At circle “2”, the CMS 114 processes the request by applying the indicated identity of the user in the request to the policies applicable to the request. For example, the CMS 114 can determine whether any CA selection policies 118 are applicable to the user account, user role, or user group associated with the identity of the user indicated in the request. In some embodiments, the CMS 114 determines the role and / or group associated with the user's identity by querying an organization service (not shown) that facilitates the creation and grouping of user accounts. Based on the user's identity, role, and / or group, the CMS 114 identifies one or more applicable CA selection policies 118. The CMS 114 then uses the domain name included in the request to evaluate the identified one or more CA selection policies 118 to determine whether a CA is specified for the request. If no policy is applicable or if there are no rules in the applicable policies, the CMS 114 can direct the request to the default CA.
[0032] In some embodiments, the CMS 114 selects (or resolves) the appropriate CA 112 as follows. First, the CMS 114 checks whether a specific CA 112 is specified in the request 126. If no CA 112 is specified in the request 126, the CMS 114 can check whether one or more user, role, and / or group policies are applicable to the request (usually from most specific to least specific). For example, the CMS 114 can check whether a user-level policy exists and specifies a CA 112 for the domain name identified in the request. If no user-level policy exists, or if a user-level policy exists but is not applicable to the domain name, the CMS 114 checks whether a group-level policy exists for the user and specifies a CA 112 for the domain name identified in the request. If no group-level policy exists, or if a group-level policy exists but is not applicable to the domain name, the CMS 114 checks whether a default CA is specified for the user's organization. If no default CA is specified for the user's organization, for all unresolved requests, the CMS 114 can defer to the default CA.
[0033] In some embodiments, the CMS 114 has a footprint in multiple regions of the cloud provider network 100. Additionally, specific regions may have different compliance requirements for CAs, and thus, for example, a CA that is available in "Region X" may not be available in "Region Y". Accordingly, the CA selection policy data 116 may include region-specific policies (not shown). When identifying applicable policies, the CMS 114 may check whether a request is received in a region with a region-specific policy. If a request is received in a region with a region-specific policy, the CMS 114 may parse one or more applicable policies from the region-specific policy.
[0034] In circle "3", the CMS 114 sends a certificate issuance request 128 to an appropriate CA 112 (e.g., a default CA, a CA identified and evaluated based on the CA selection policy, the CA specified in the request 126, etc.) at least in part based on the request 126. In this example, the CMS 114 sends the request 128 to the CA 112C and receives a response 129 from the CA 112C. In circle "4", the CMS 114 receives a certificate issuance response 129 from the CA 112C. The response 129 may include the issued certificate or a reference to the issued certificate stored in a certificate data repository (not shown).
[0035] In circle "5", the CMS 114 sends a certificate issuance response 130 to the electronic device 102A at least in part based on the certificate issuance response 129. Again, the response 130 may include the issued certificate or a reference to the issued certificate stored in a certificate data repository (not shown).
[0036] In some embodiments, the certificate issuance request and the certificate issuance response may respectively originate from and return to an electronic device 102B within the provider network 100.
[0037] Figure 2 FIG. is a diagram illustrating an environment for configuring a certificate authority selection policy according to some embodiments. An exemplary set of operations of the CMS 114 related to the configuration of the CA selection policy will now be described with reference to the circled numbers 1 through 2.
[0038] In circle "1", a user, such as a PKI administrator, uses an electronic device 202A to send a request 226 to the CMS 114 to configure the CA selection policy 118. For example, such a user may be responsible for or otherwise desire to configure a set of CA selection rules within an organization to apply to the organization's users, roles, and / or groups. This ability of a user to define a CA selection policy applicable to a group or role alleviates the burden of coordinating certificate issuance within the organization.
[0039] In some embodiments, the definition of the CA selection policy 118 generally includes one or more rules and an identification of the user or group of users to which the policy applies. The rules associate a domain name or other identifier with a certificate that will be associated with a CA (e.g., Figure 1 one of the CAs 112 in Figure 3 ). Reference
[0040] shows and describes an exemplary CA selection policy.
[0041] In some embodiments, the selected users or roles to which the policy or rule will be applied can be selected based on a selection of a user account, role, user group, organization, or other user or role grouping, where such user accounts, roles, user groups, and organizations can be defined using the identity and access management services provided by the cloud provider network 100 or using an identity and access management system controlled by the organization that configures the policy.
[0042] Exemplary configuration requests 226 include requests to create a new CA selection policy, requests to update an existing CA selection policy, and requests to delete a CA selection policy. A request to create a new CA selection policy generally includes one or more rules and an identification of the user or group of users to which the policy applies. A request to update an existing CA selection policy generally includes an identification of the policy to be updated (usually identified using the policy identifier returned when the policy was created, or when the user lists the existing policies) and any updates to the policy. For example, the update can take the form of a separate addition or deletion of the applicability or rules specified in the policy, or the replacement of the existing applicability or rules of the policy with new applicability or rules. A request to delete an existing CA selection policy generally includes an identification of the policy to be deleted.
[0043] In circle “2”, the CMS 114 processes request 226. For example, the CMS 114 creates a new CA selection policy in response to a policy creation request, deletes an existing CA selection policy in response to a policy deletion request, or updates an existing policy in response to a policy update request. The CMS 114 may store newly created certificates, update existing certificates, or delete certificates from a certificate data repository (not shown). In some embodiments, the CMS 114 returns an identification of the created, updated, or deleted policy to the originator of the configuration request 226.
[0044] In some embodiments, the policy configuration request may originate from an electronic device 102B within the provider network 100.
[0045] Figure 3 FIG. is a diagram showing an exemplary certificate authority selection policy 300 according to some embodiments. As shown, a CA selection policy generally includes one or more rules and an identification of the user or group of users to which the policy applies. Exemplary CA selection policy 300 includes applicability 301 and rules 302. In this example, the applicability 301 is for the group “DEV_TEAM”, so users associated with this group may have the CA selection policy 300 applied by the CMS 114 (e.g., if no more specific policy applies). As discussed, in some embodiments, the applicability of a policy may be stored separately from the policy data (e.g., rules) that is metadata associated with the corresponding policy.
[0046] Rule 302 associates a domain name or other identifier 303 with an identifier of a CA 304 (such as CA 112). Exemplary CA selection policy 300 includes four rules. One rule associates a subdomain of the domain subramanian.com with a CA having the identifier “CA012”. Another rule associates a subdomain of the domain hess.com with a CA having the identifier “CA345”. Another rule associates a subdomain of the domain levy.com with a CA having the identifier “CA678”. Another rule associates all unspecified (e.g., default) domains with a CA having the identifier “CA9AB”. The CA identifier 304 (e.g., “CA012”, “CA345”, “CA678”, and “CA9AB”) may directly or indirectly identify various CAs (e.g., via a network address, alias, domain name, etc.).
[0047] For example, CA selection strategies such as CA selection strategies 118 and 300 can be stored as a structured representation (e.g., in JSON format) that includes the rules contained in the strategy and, optionally, as a text document or other data structure for the applicability of the strategy. For example, each strategy and / or rule can be specified and stored in a structured representation that identifies one or more users or groups to which the strategy or rule applies and the structured representation of one or more rules. As described herein, the applicability of a particular CA selection strategy can be stored with the strategy or as metadata separate from the strategy itself. For each strategy, such metadata about the strategy in the CA selection strategy data can include an identifier for the strategy and the applicability of this strategy. The CMS 114 can evaluate the strategy applicability metadata to determine whether any strategy applies to a given certificate-related request.
[0048] Figure 4 is a diagram showing an environment in which different certificate authorities are selected according to some embodiments. As shown, the cloud provider network 100 includes two CAs - a public CA 412A denoted as "CA_A" and a private CA 412B denoted as "CA_B". The CA selection strategy data 416 includes a CA selection strategy 418A associated with a user, a CA selection strategy 418B associated with a group that includes the user, and a default CA policy 420. The CA selection strategy 418A includes a rule indicating that certificate requests associated with subdomains of subramanian.com will be processed by CA_A (CA 412A). The CA selection strategy 418B includes a rule indicating that certificate requests associated with subdomains of hess.com will be processed by CA_B (CA 412B). And the default CA 420 identifies CA_A (CA 412A).
[0049] In this example, a user of the electronic device 402 submits three certificate creation requests to the CMS 114 via one or more intermediate networks 104 (e.g., the Internet) via one or more interfaces 108 to the cloud provider network 100. The operations associated with the first request are described with reference to the circled 1A to 3A; the operations associated with the second request are described with reference to the circled 1B to 3B; and the operations associated with the third request are described with reference to the circled 1C to 3C.
[0050] In a first certificate creation request, at circle "1A", a user using electronic device 402 sends a request for a new certificate to CMS 114. The request includes an indication of the user's identity. In this example, we assume the user's identity is "User A". The request also includes the domain name (blog.subramanian.com) for which the certificate is to be created. At circle "2A", CMS 114 identifies the CA selection policy 418A associated with User A (e.g., based on the included applicability data or other metadata). CMS 114 then evaluates the policy using the content of the request. Here, the CA selection policy 418A includes a rule indicating that a certificate for a subdomain of subramanian.com will be issued by CA_A (CA 412A). At circle "3A", CMS 114 sends the request to the identified CA (CA_A). Then, the issuance response (either the certificate or a reference to the certificate) is sent back from CA 412A to the electronic device 402 via CMS 114.
[0051] In a second certificate creation request, at circle "1B", a user using electronic device 402 sends a request for a new certificate to CMS 114. Again, the request includes an indication of the user's identity (User A). The request also includes the domain name (docs.hess.com) for which the certificate is to be created. At circle "2B", CMS 114 first identifies and checks the CA selection policy 418A associated with User A and determines that the CA policy 418A does not have a rule applicable to the hess.com domain. CMS 114 also identifies the group (or role) CA selection policy 418B applicable to the group or role that includes the identified user. Here, the group CA selection policy 418B includes a rule indicating that a certificate for a subdomain of hess.com will be issued by CA_B (CA 412B). At circle "3B", CMS 114 sends the request to the identified CA (CA_B). Then, the issuance response (either the certificate or a reference to the certificate) is sent back from CA 412B to the electronic device 402 via CMS 114.
[0052] In a third certificate creation request, at circle "1C", a user of the electronic device 402 sends a request for a new certificate to the CMS 114. Again, the request includes an indication of the identity of the user (User A). The request also includes the domain name (images.levy.com) for which the certificate is to be created. At circle "2C", the CMS 114 first identifies and examines the CA selection policy 418A associated with User A and determines that the CA policy 418A does not have a rule applicable to the levy.com domain. The CMS 114 also identifies the group (or role) CA selection policy 418B applicable to the group or role that includes the identified user and determines that the CA policy 418B also does not have a rule applicable to the levy.com domain. The CMS 114 has a default CA policy 420 indicating that requests not processed by other policies will be issued by CA_A (CA 412A). At circle "3C", the CMS 114 sends the request to the identified default CA (CA_A). Then, the issued response (whether a certificate or a reference to a certificate) is sent back from the CA 412A to the electronic device 402 via the CMS 114.
[0053] Figure 5 is a flowchart of operation 500 of a method for certificate authority selection according to some embodiments. Some or all of operation 500 (or other processes described herein, or variations and / or combinations thereof) are performed under the control of one or more computer systems configured with executable instructions and implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that execute together on one or more processors. The code is stored, for example, in the form of a computer program including instructions executable by one or more processors on a computer-readable storage medium. The computer-readable storage medium is non-transitory. In some embodiments, one or more (or all) of operation 500 are performed by the CMS 114 of other figures.
[0054] Operation 500 includes, at block 502, receiving a first request to generate a certificate from an electronic device and through a certificate management service of a cloud provider network, where the first request includes an indication of the identity of the user and an identification of the domain name to be associated with the certificate.
[0055] Operation 500 further includes, at block 504, identifying a first certificate authority selection policy applicable to the first request, where the first certificate authority selection policy includes certificate authority selection rules.
[0056] Operation 500 further includes, at block 506, evaluating the certificate authority selection rules to identify a certificate authority for generating the certificate, where the certificate authority selection rules associate at least a portion of the domain name with the certificate authority.
[0057] Operation 500 further includes, at block 508, sending a second request to a certificate authority to generate a certificate.
[0058] Operation 500 further includes, at block 510, returning the certificate or an identifier of the certificate from the certificate authority to the electronic device.
[0059] In some embodiments, the first request does not include an identifier of any certificate authority.
[0060] In some embodiments, prior to evaluating the certificate authority selection rule, a second certificate authority selection strategy applicable to the first request is identified and it is determined that the second certificate authority selection strategy does not include a rule associated with a domain name. In such a case, for example, the first certificate authority selection strategy may be associated with a group including the identity of the user, and the second certificate authority selection strategy may be associated with the identity of the user.
[0061] In some embodiments, the CMS receives a third request to create a first certificate authority selection strategy, where the third request includes (a) an association of at least a part of a domain name with a certificate authority, and (b) a policy applicability that associates the first certificate authority selection strategy with at least one of (i) the identity of the user, (ii) a role associated with the identity of the user, or (iii) a group including the identity of the user, and the CMS stores the first certificate authority selection strategy in a data repository. The policy applicability may be stored in metadata associated with the first certificate authority selection strategy or stored as part of the first certificate authority selection strategy.
[0062] In some embodiments, the certificate authority is (a) a private certificate authority service configured to be used by an administrator of an organization including the user, or (b) a public certificate authority, where the public certificate authority is a service of a cloud provider network or a third party.
[0063] In some embodiments, the first certificate authority selection strategy applies to the first request by at least one of the following: (a) the first certificate authority selection strategy is associated with the identity of the user, (b) the first certificate authority selection strategy is associated with a role associated with the identity of the user, (c) the first certificate authority selection strategy is associated with a group including the identity of the user, or (d) the first certificate authority selection strategy is a default strategy.
[0064] In some embodiments, the first certificate authority selection strategy is associated with a geographic region, and the first certificate authority selection strategy applies to the first request at least in part based on the first request being received by a certificate management service in the geographic region.
[0065] In some embodiments, the certificate authority is one of a plurality of certificate authorities available to the user.
[0066] Figure 6 Illustrates an exemplary provider network (or "service provider system") environment according to some embodiments. Provider network 600 may provide resource virtualization to customers via one or more virtualization services 610, which allow customers to purchase, lease, or otherwise obtain instances 612 of virtualized resources (including but not limited to computing resources and storage resources) implemented on devices within one or more provider networks in one or more data centers. A local Internet Protocol (IP) address 616 may be associated with resource instance 612; the local IP address is the internal network address of resource instance 612 on provider network 600. In some embodiments, provider network 600 may also provide a public IP address 614 and / or a public IP address range (e.g., Internet Protocol version 4 (IPv4) or Internet Protocol version 6 (IPv6) address) that a customer may obtain from provider 600.
[0067] Conventionally, provider network 600 may, via virtualization services 610, allow customers of the service provider (e.g., customers operating one or more customer networks 650A to 650C (or "client networks") including one or more customer devices 652) to dynamically associate at least some of the public IP addresses 614 allocated or assigned to the customer with a particular resource instance 612 assigned to the customer. Provider network 600 may also allow a customer to remap a public IP address 614 previously mapped to one virtualized computing resource instance 612 assigned to the customer to another virtualized computing resource instance 612 also assigned to the customer. Using the virtualized computing resource instances 612 and public IP addresses 614 provided by the service provider, customers of the service provider, such as the operators of customer networks 650A to 650C, may, for example, implement customer-specific applications and present the customer's application programs on an intermediate network 640 (such as the Internet). Other network entities 620 on intermediate network 640 may then generate traffic to the destination public IP address 614 published by customer networks 650A to 650C; the traffic is routed to the service provider data center and, at the data center, is routed via the network substrate to the local IP address 616 of the virtualized computing resource instance 612 currently mapped to the destination public IP address 614. Similarly, response traffic from virtualized computing resource instance 612 may be routed back via the network substrate to source entity 620 on intermediate network 640.
[0068] As used herein, a local IP address refers to, for example, an internal or "private" network address of a resource instance in a provider network. A local IP address may be within the address blocks reserved by Request for Comments (RFC) 1918 of the Internet Engineering Task Force (IETF) and / or have an address format specified by IETF RFC 4193, and may be variable within the provider network. Network traffic originating outside the provider network is not directly routed to the local IP address; rather, the traffic uses a public IP address that is mapped to the local IP address of the resource instance. The provider network may include networking devices or equipment that provide network address translation (NAT) or similar functionality to perform the mapping from the public IP address to the local IP address and from the local IP address to the public IP address.
[0069] A public IP address is an Internet-variable network address assigned to a resource instance by a service provider or a customer. Traffic is routed, for example, via a 1:1 NAT translation to the public IP address and forwarded to the corresponding local IP address of the resource instance.
[0070] Some public IP addresses may be assigned by the provider network infrastructure to specific resource instances; these public IP addresses may be referred to as standard public IP addresses, or simply standard IP addresses. In some embodiments, the mapping from the standard IP address to the local IP address of the resource instance is the default startup configuration for all resource instance types.
[0071] At least some public IP addresses may be allocated to customers of the provider network 600 or obtained by customers of the provider network; then, the customer may assign their allocated public IP address to a specific resource instance assigned to the customer. These public IP addresses may be referred to as customer public IP addresses, or simply customer IP addresses. Instead of being assigned to the resource instance by the provider network 600 as in the case of standard IP addresses, the customer IP address may be assigned to the resource instance by the customer, for example, via an API provided by the service provider. Different from the standard IP address, the customer IP address is assigned to a customer account and may be remapped to other resource instances by the corresponding customer as needed or desired. The customer IP address is associated with the customer account rather than a specific resource instance, and the customer controls the IP address until the customer chooses to release the IP address. Different from a conventional static IP address, the customer IP address allows the customer to mask resource instance or availability zone failures by remapping the customer's public IP address to any resource instance associated with the customer account. For example, the customer IP address enables the customer to resolve problems with the customer's resource instance or software by remapping the customer IP address to an alternative resource instance.
[0072] Figure 7FIG. 0 is a block diagram of an example provider network environment that provides storage services and hardware virtualization services to customers according to some embodiments. The hardware virtualization service 720 provides a plurality of computing resources 724 (e.g., computing instances 725 such as VMs) to customers. The computing resources 724 can be provided as a service, for example, to customers of the provider network 700 (e.g., customers implementing the customer network 750). Each computing resource 724 can be provided with one or more local IP addresses. The provider network 700 can be configured to route packets from the local IP addresses of the computing resources 724 to public Internet destinations and to route packets from public Internet sources to the local IP addresses of the computing resources 724.
[0073] The provider network 700 can provide, for example, the customer network 750 coupled to the intermediate network 740 via the local network 756 with the ability to implement a virtual computing system 792 via the hardware virtualization service 720 coupled to the intermediate network 740 and the provider network 700. In some embodiments, the hardware virtualization service 720 can provide one or more APIs 702, such as a web service interface, via which the customer network 750 can access the functions provided by the hardware virtualization service 720, for example, via the console 794 of the customer device 790 (e.g., web-based application, stand-alone application, mobile application, etc.). In some embodiments, at the provider network 700, each virtual computing system 792 at the customer network 750 can correspond to the computing resources 724 leased, rented, or otherwise provided to the customer network 750.
[0074] From an instance of the virtual computing system 792 and / or another customer device 790 (e.g., via the console 794), a customer can access the functions of the storage service 710, for example, via one or more APIs 702, to access data from the storage resources 718A to 718N of the virtual data repository 716 (e.g., folder or "bucket", virtualized volume, database, etc.) provided by the provider network 700 and to store data into the storage resources. In some embodiments, a virtualized data storage gateway (not shown) can be provided at the customer network 750, which can locally cache at least some data (e.g., frequently accessed data or critical data) and can communicate with the storage service 710 via one or more communication channels to upload new or modified data from the local cache, so as to maintain the primary data repository (virtualized data repository 716). In some embodiments, a user can install and access volumes of the virtual data repository 716 via the storage service 710 acting as a storage virtualization service via the virtual computing system 792 and / or another customer device 790, and these volumes can appear to the user as local (virtualized) storage 798.
[0075] Although Figure 7Although not shown, the virtualization service can also be accessed from a resource instance within the provider network 700 via the API 702. For example, a customer, a device service provider, or other entity can access the virtualization service from within a corresponding virtual network on the provider network 700 via the API 702 to request allocation of one or more resource instances within the virtual network or within another virtual network.
[0076] Illustrative system
[0077] In some embodiments, a system that implements some or all of the techniques described herein may include a general-purpose computer system (such as Figure 8 the computer system 800 shown), the general-purpose computer system including or being configured to access one or more computer-accessible media. In the illustrated embodiment, the computer system 800 includes one or more processors 810 coupled to a system memory 820 via an input / output (I / O) interface 830. The computer system 800 also includes a network interface 840 coupled to the I / O interface 830. Although Figure 8 the computer system 800 is shown as a single computing device, in various embodiments, the computer system 800 may include one computing device or any number of computing devices configured to work together as a single computer system 800.
[0078] In various embodiments, the computer system 800 can be a single-processor system including one processor 810 or a multi-processor system including several processors 810 (e.g., two, four, eight, or another suitable number). The processor 810 can be any suitable processor capable of executing instructions. For example, in various embodiments, the processor 810 can be a general-purpose or embedded processor implementing any one of a variety of instruction set architectures (ISAs) (such as, x86, ARM, PowerPC, SPARC, or MIPS ISA or any other suitable ISA). In a multi-processor system, each of the processors 810 typically may but need not implement the same ISA.
[0079] System memory 820 may store instructions and data accessible by processor 810. In various embodiments, system memory 820 may be implemented using any suitable memory technology, such as random access memory (RAM), static RAM (SRAM), synchronous dynamic RAM (SDRAM), non-volatile / flash-type memory, or any other type of memory. In the illustrated embodiment, program instructions and data for implementing one or more desired functions (such as those methods, techniques, and data described above) are shown as stored within system memory 820 as CMS code 825 (e.g., executable to implement CMS114 in whole or in part) and data 826 (such as CA selection strategy data 116, 416).
[0080] In some embodiments, I / O interface 830 may be configured to coordinate I / O traffic between processor 810, system memory 820, and any peripheral devices in the apparatus, including network interface 840 and / or other peripheral interfaces (not shown). In some embodiments, I / O interface 830 may perform any necessary protocol, timing, or other data transformations to convert data signals from one component (e.g., system memory 820) into a format suitable for use by another component (e.g., processor 810). In some embodiments, for example, I / O interface 830 may include support for devices attached via various types of peripheral buses, such as variants of the Peripheral Component Interconnect (PCI) bus standard or the Universal Serial Bus (USB) standard. In some embodiments, for example, the functionality of I / O interface 830 may be split into two or more separate components, such as a north bridge and a south bridge. Additionally, in some embodiments, some or all of the functionality of I / O interface 830 (such as the interface to system memory 820) may be incorporated directly into processor 810.
[0081] For example, network interface 840 may be configured to permit exchange of data between computer system 800 and other devices 860 attached to one or more networks 850 (such as other computer systems or devices as shown). In various embodiments, for example, network interface 840 may support communication via any suitable wired or wireless general data network, such as various types of Ethernet networks. Additionally, network interface 840 may support communication via a telecommunications / telephone network (such as an analog voice network or a digital fiber-optic communication network), via a storage area network (SAN) (such as a Fibre Channel SAN), and / or via any other suitable type of network and / or protocol. Figure 1 shown)
[0082] In some embodiments, computer system 800 includes one or more offload cards 870A or 870B (including one or more processors 875 and possibly including one or more network interfaces 840), which are connected using an I / O interface 830 (e.g., a version of the Peripheral Component Interconnect Express (PCI-E) standard or a bus of another interconnect such as QuickPath Interconnect (QPI) or UltraPath Interconnect (UPI)). For example, in some embodiments, computer system 800 may act as a host electronic device that hosts computing resources such as computing instances (e.g., operating as part of a hardware virtualization service), and one or more offload cards 870A or 870B execute a virtualization manager that can manage the computing instances executed on the host electronic device. As an example, in some embodiments, one or more offload cards 870A or 870B may perform computing instance management operations such as pausing and / or unpausing a computing instance, starting and / or terminating a computing instance, performing memory transfer / copy operations, etc. In some embodiments, these management operations may be performed by one or more offload cards 870A or 870B in cooperation with a hypervisor (e.g., in accordance with a request from the hypervisor) executed by other processors 810A to 810N of computer system 800. However, in some embodiments, the virtualization manager implemented by offload cards 870A or 870B may accommodate requests from other entities (e.g., from the computing instance itself) and may not cooperate with (or serve) any separate hypervisor.
[0083] In some embodiments, system memory 820 may be an embodiment of a computer-accessible medium configured to store program instructions and data as described above. However, in other embodiments, program instructions and / or data may be received, sent, or stored on different types of computer-accessible media. Generally, computer-accessible media may include any non-transitory storage medium or memory medium, such as magnetic or optical media, e.g., a disk or DVD / CD coupled to computer system 800 via I / O interface 830. Non-transitory computer-accessible storage media may also include any volatile or non-volatile media that may be included as system memory 820 or another type of memory in some embodiments of computer system 800, such as RAM (e.g., SDRAM, Double Data Rate (DDR) SDRAM, SRAM, etc.), read-only memory (ROM), etc. Additionally, computer-accessible media may include a transmission medium or signals transmitted via a communication medium such as a network and / or a wireless link, such as electrical, electromagnetic, or digital signals, where the communication medium may be implemented via network interface 840.
[0084] The various embodiments discussed or presented herein can be implemented in a variety of operating environments. In some cases, the operating environment can include one or more user computers, computing devices, or processing devices that can be used to operate any of a number of applications. The user device or client device can include any of a number of general-purpose personal computers, such as a desktop or laptop computer running a standard operating system, as well as cellular devices, wireless devices, and handheld devices that run mobile software and are capable of supporting a number of networking and messaging protocols. Such a system can also include a number of workstations that run various commercially available operating systems and any of a number of other known applications for purposes such as development and database management. These devices can also include other electronic devices, such as dumb terminals, thin clients, gaming systems, and / or other devices capable of communicating over a network.
[0085] Most embodiments use at least one network familiar to those skilled in the art to support communication using any of a variety of widely available protocols, such as the Transmission Control Protocol / Internet Protocol (TCP / IP), File Transfer Protocol (FTP), Universal Plug and Play (UPnP), Network File System (NFS), Common Internet File System (CIFS), Extensible Messaging and Presence Protocol (XMPP), AppleTalk, etc. The network can include, for example, a Local Area Network (LAN), a Wide Area Network (WAN), a Virtual Private Network (VPN), the Internet, an intranet, an extranet, a Public Switched Telephone Network (PSTN), an infrared network, a wireless network, and any combination thereof.
[0086] In embodiments that use a web server, the web server can run any of a variety of server or middle-tier applications, including an HTTP server, a File Transfer Protocol (FTP) server, a Common Gateway Interface (CGI) server, a data server, a Java server, a business application server, etc. The server may also be capable of executing programs or scripts in response to requests from user devices, such as by executing one or more web applications that can be implemented as one or more scripts or programs written in any programming language (such as C, C#, or C++) or any scripting language (such as Perl, Python, PHP, or TCL) and combinations thereof. The server can also include a database server, including but not limited to database servers commercially available from Oracle(R), Microsoft(R), Sybase(R), IBM(R), etc. The database server can be relational or non-relational (e.g., “NoSQL”), distributed or non-distributed, etc.
[0087] The environments disclosed herein may include various data repositories as well as other memories and storage media as discussed above. These may reside in various locations, such as on storage media local to (and / or residing within) one or more computers, or on storage media remote from any or all of the computers on a network. In a particular set of embodiments, the information may reside in a storage area network (SAN) familiar to those skilled in the art. Similarly, any necessary files for performing the functions attributed to a computer, server, or other network device may be stored locally and / or remotely as appropriate. In cases where the system includes computerized devices, each such device may include hardware elements electrically coupled via a bus, the elements including, for example, at least one central processing unit (CPU), at least one input device (e.g., a mouse, keyboard, controller, touch screen, or keypad), and / or at least one output device (e.g., a display device, printer, or speaker). Such a system may also include one or more storage devices, such as disk drives, optical storage devices, and solid state storage devices (such as random access memory (RAM) or read only memory (ROM)), as well as removable media devices, memory cards, flash cards, etc.
[0088] Such devices may also include a computer-readable storage medium reader, a communication device (e.g., a modem, network card (wireless or wired), infrared communication device, etc.), and a working memory as described above. The computer-readable storage medium reader may be connected to or configured to receive a computer-readable storage medium, which represents remote, local, fixed, and / or removable storage devices and storage media for temporarily and / or more permanently containing, storing, transmitting, and retrieving computer-readable information. The system and various devices will generally also include many software applications, modules, services, or other elements located within at least one working memory device, including an operating system and application programs, such as client applications or web browsers. It should be appreciated that alternative embodiments may have many variations different from those described above. For example, custom hardware may also be used, and / or particular elements may be implemented in hardware, software (including portable software, such as applets), or both. Additionally, connections to other computing devices, such as network input / output devices, may be employed.
[0089] Storage media and computer-readable media for containing code or code portions may include any suitable media known or used in the art, including storage media and communication media, such as but not limited to volatile and non-volatile media, removable and non-removable media implemented in any method or technology to store and / or transmit information (such as computer-readable instructions, data structures, program modules or other data), including RAM, ROM, electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk-read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage device, magnetic cassette, magnetic tape, magnetic disk storage device or other magnetic storage device or any other medium that can be used to store the desired information and can be accessed by the system device. Based on the present disclosure and the teachings provided herein, ordinary technicians in the art will understand other ways and / or methods of implementing various embodiments.
[0090] In the foregoing description, various embodiments are described. For explanation purposes, specific configurations and details are set forth in order to provide a thorough understanding of the embodiments. However, it will also be apparent to those skilled in the art that the embodiments may be practiced without these specific details. In addition, in order not to obscure the described embodiments, well-known features may be omitted or simplified.
[0091] Parenthesized text and boxes with dashed borders (e.g., large dashes, small dashes, dot dashes, and dots) are used herein to illustrate optional aspects that add additional features to some embodiments. However, this notation should not be taken to mean that these are the only options or optional operations, and / or that in certain embodiments, boxes with solid borders are not optional.
[0092] Reference numerals with suffix letters (e.g., 718A-718N) may be used to indicate that there may be one or more instances of the referenced entity in various embodiments, and when there are multiple instances, each instance need not be identical, but may share some general characteristics or function in a common manner. In addition, the particular suffix used is not meant to imply that there is a particular number of entities unless specifically indicated to the contrary. Thus, in various embodiments, two entities using the same or different suffix letters may or may not have the same number of instances.
[0093] References to "one embodiment", "an embodiment", "example embodiment", etc., indicate that the described embodiment may include a particular feature, structure, or characteristic, but each embodiment may not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is to be understood that implementing such feature, structure, or characteristic in connection with other embodiments is within the knowledge of those skilled in the art, whether or not explicitly described.
[0094] Moreover, in the various embodiments described above, unless otherwise specifically specified, disjunctive language such as the phrase "at least one of A, B, or C" is intended to be understood to mean A, B, or C, or any combination thereof (e.g., A, B, and / or C). Similarly, language such as "at least one or more of A, B, and C" (or "one or more of A, B, and C") is intended to be understood to mean A, B, or C, or any combination thereof (e.g., A, B, and / or C). Thus, disjunctive language is not intended and should not be understood to imply that a given embodiment requires the presence of at least one of each of A, at least one of each of B, and at least one of each of C.
[0095] As used herein, the term "based on" (or similar) is an open-ended term used to describe one or more factors that affect a determination or other action. It should be understood that the term does not exclude additional factors that may affect the determination or action. For example, the determination may be based solely on the listed factors or based on the stated factors and one or more additional factors. Thus, if action A is "based on" B, it should be understood that B is one factor that affects action A, but this does not exclude the action also being based on one or more other factors, such as factor C. However, in some cases, action A may be based entirely on B.
[0096] Unless otherwise explicitly stated, articles such as "a / an" are generally to be interpreted as including one or more of the described items. Thus, phrases such as "a device configured to..." or "a computing device" are intended to include one or more of the stated devices. These one or more stated devices may be jointly configured to perform the stated operations. For example, "a processor configured to perform operations A, B, and C" may include a first processor configured to perform operation A working together with a second processor configured to perform operations B and C.
[0097] Additionally, the words "may" or "can" are used in a permissive sense (i.e., meaning having a certain possibility), rather than in a mandatory sense (i.e., meaning must). The words "include", "including", and "includes" are used to indicate an open-ended relationship and thus mean including but not limited to. Similarly, the words "have", "having", and "has" also indicate an open-ended relationship and thus mean having but not limited to. The terms "first", "second", "third", etc. used herein serve as labels for the nouns following them and do not imply any type of order (e.g., spatial, temporal, logical, etc.) unless such order is explicitly specified otherwise.
[0098] At least some embodiments of the disclosed technology may be described in view of the following clauses:
[0099] 1. A computer-implemented method, comprising:
[0100] Receiving, by a certificate management service of a cloud provider network, a first request to create a first certificate authority selection policy, wherein the first request includes: (a) an association of a first domain name with a certificate authority, and (b) a policy applicability associating the first certificate authority selection policy with at least one of: (i) the identity of a user, (ii) a role associated with the identity of the user, or (iii) a group including the identity of the user;
[0101] Storing the first certificate authority selection policy and the policy applicability in a data repository, wherein the first certificate authority selection policy includes a certificate authority selection rule associating the first domain name with a certificate authority;
[0102] Receiving, from an electronic device and by the certificate management service, a second request to generate a certificate, wherein the second request includes an indication of the identity of a user and an identification of a second domain name to be associated with the certificate;
[0103] Identifying, at least in part based on the policy applicability, a first certificate authority selection policy applicable to the second request;
[0104] Evaluating, at least in part based on the second domain name being a subdomain of the first domain name, the certificate authority selection rule to identify a certificate authority;
[0105] Sending a third request to generate a certificate to the certificate authority; and
[0106] Returning a certificate or an identification of a certificate from the certificate authority to the electronic device.
[0107] 2. The computer-implemented method according to clause 1, wherein the second request does not include an identification of any certificate authority.
[0108] 3. The computer-implemented method as described in any one of clauses 1-2, further comprising:
[0109] Before evaluating the certificate authority selection rules:
[0110] Identify a second certificate authority selection strategy applicable to the first request; and
[0111] Determine that the second certificate authority selection strategy does not include rules associated with the second domain name.
[0112] 4. A computer-implemented method, comprising:
[0113] Receiving, from an electronic device and via a certificate management service of a cloud provider network, a first request to generate a certificate, wherein the first request includes an indication of the identity of a user and an identification of a domain name to be associated with the certificate;
[0114] Identifying a first certificate authority selection strategy applicable to the first request, wherein the first certificate authority selection strategy includes certificate authority selection rules;
[0115] Evaluating the certificate authority selection rules to identify a certificate authority for generating the certificate, wherein the certificate authority selection rules associate at least a portion of the domain name with the certificate authority;
[0116] Sending a second request to generate the certificate to the certificate authority; and
[0117] Returning the certificate or an identification of the certificate from the certificate authority to the electronic device.
[0118] 5. The computer-implemented method as described in clause 4, wherein the first request does not include an identification of any certificate authority.
[0119] 6. The computer-implemented method as described in any one of clauses 4-5, further comprising:
[0120] Before evaluating the certificate authority selection rules:
[0121] Identifying a second certificate authority selection strategy applicable to the first request; and
[0122] Determining that the second certificate authority selection strategy does not include rules associated with the domain name.
[0123] 7. The computer-implemented method as described in clause 6, wherein the first certificate authority selection strategy is associated with a group including the identity of the user, and the second certificate authority selection strategy is associated with the identity of the user.
[0124] 8. The computer-implemented method as described in any one of clauses 4-7, further comprising:
[0125] Receive a third request to create a first certificate authority selection policy from a certificate management service, where the third request includes (a) an association of at least a portion of a domain name with a certificate authority, and (b) a policy applicability that associates the first certificate authority selection policy with at least one of the following: (i) the identity of a user, (ii) a role associated with the identity of the user, or (iii) a group that includes the identity of the user; and
[0126] Store the first certificate authority selection policy in a data repository.
[0127] 9. The computer-implemented method as described in clause 8, wherein the policy applicability is stored in metadata associated with the first certificate authority selection policy.
[0128] 10. The computer-implemented method as described in any one of clauses 4-9, wherein the certificate authority is (a) a private certificate authority service configured for use by an administrator of an organization that includes the user, or (b) a public certificate authority, where the public certificate authority is a service of a cloud provider network or a third party.
[0129] 11. The computer-implemented method as described in any one of clauses 4-10, wherein the first certificate authority selection policy applies to the first request through at least one of the following: (a) the first certificate authority selection policy is associated with the identity of the user, (b) the first certificate authority selection policy is associated with a role associated with the identity of the user, (c) the first certificate authority selection policy is associated with a group that includes the identity of the user, or (d) the first certificate authority selection policy is a default policy.
[0130] 12. The computer-implemented method as described in clause 11, wherein the first certificate authority selection policy is associated with a geographic region, and wherein the first certificate authority selection policy also applies to the first request at least in part based on the first request being received by a certificate management service in the geographic region.
[0131] 13. The computer-implemented method as described in any one of clauses 4-12, wherein the certificate authority is one of multiple certificate authorities available to the user.
[0132] 14. A system, comprising:
[0133] One or more first electronic devices for implementing a data storage service of a cloud provider network, the data storage service including instructions that, when executed, cause the data storage service to store certificate authority selection policy data; and
[0134] One or more second electronic devices for implementing a certificate management service of a cloud provider network, the certificate management service including instructions that, when executed, cause the certificate management service to perform the following operations:
[0135] Receive a first request to generate a certificate from a third electronic device, where the first request includes an indication of the identity of a user and an identification of a domain name to be associated with the certificate;
[0136] Identify a first certificate authority selection policy applicable to the first request and in the certificate authority selection policy data, where the first certificate authority selection policy includes certificate authority selection rules;
[0137] Evaluate the certificate authority selection rules to identify a certificate authority to be used to generate the certificate, where the certificate authority selection rules associate at least a portion of the domain name with a certificate authority;
[0138] Send a second request to generate the certificate to the certificate authority; and
[0139] Return the certificate or an identification of the certificate from the certificate authority to the third electronic device.
[0140] 15. The system according to clause 14, where the first request does not include an identification of any certificate authority.
[0141] 16. The system according to any one of clauses 14 - 15, the certificate management service including additional instructions that, when executed, cause the certificate management service to perform the following operations:
[0142] Before evaluating the certificate authority selection rules:
[0143] Identify a second certificate authority selection policy applicable to the first request; and
[0144] Determine that the second certificate authority selection policy does not include rules associated with the domain name.
[0145] 17. The system according to clause 16, where the first certificate authority selection policy is associated with a group including the identity of the user, and the second certificate authority selection policy is associated with the identity of the user.
[0146] 18. The system according to any one of clauses 14 - 17, the certificate management service including additional instructions that, when executed, cause the certificate management service to perform the following operations:
[0147] Receive a third request to create a first certificate authority selection policy, where the third request includes (a) an association of at least a portion of the domain name with a certificate authority, and (b) a policy applicability that associates the first certificate authority selection policy with at least one of the following: (i) the identity of the user, (ii) a role associated with the identity of the user, or (iii) a group including the identity of the user; and
[0148] Store the first certificate authority selection policy in the certificate authority selection policy data.
[0149] 19. The system as described in clause 18, wherein the policy applicability is stored as metadata in the certificate authority selection policy data and is associated with the first certificate authority selection policy.
[0150] 20. The system as described in any one of clauses 14 - 19, wherein the certificate authority is (a) a private certificate authority service configured for use by an administrator of an organization including the user, or (b) a public certificate authority, where the public certificate authority is a service of a cloud provider network or a third party.
[0151] The specification and drawings are accordingly to be regarded in an illustrative rather than a restrictive sense. However, it will be apparent that various modifications and changes may be made thereto without departing from the broader spirit and scope of the disclosure as set forth in the claims.
Claims
1. A computer-implemented method, comprising: Receiving, by a certificate management service of a cloud provider network, a first request to create a first certificate authority selection policy, wherein the first request includes: (a) an association of a first domain name with a certificate authority, and (b) a policy applicability that associates the first certificate authority selection policy with at least one of: (i) the identity of a user, (ii) a role associated with the identity of the user, or (iii) a group that includes the identity of the user; Storing the first certificate authority selection policy and the policy applicability in a data repository, wherein the first certificate authority selection policy includes a certificate authority selection rule that associates the first domain name with the certificate authority; Receiving, from an electronic device and by the certificate management service, a second request to generate a certificate, wherein the second request includes an indication of the identity of the user and an identification of a second domain name to be associated with the certificate; Identifying, at least in part based on the policy applicability, the first certificate authority selection policy applicable to the second request; Evaluating, at least in part based on the second domain name being a subdomain of the first domain name, the certificate authority selection rule to identify the certificate authority; Sending a third request to generate the certificate to the certificate authority; and Returning, from the certificate authority to the electronic device, the certificate or an identification of the certificate.
2. The computer-implemented method according to claim 1, wherein the second request does not include an identification of any certificate authority.
3. The computer-implemented method according to claim 1, further comprising: Before evaluating the certificate authority selection rule: Identifying a second certificate authority selection policy applicable to the first request; And Determining that the second certificate authority selection policy does not include a rule associated with the second domain name.
4. A computer-implemented method, comprising: Receiving, from an electronic device and through a certificate management service of a cloud provider network, a first request to generate a certificate, wherein the first request includes an indication of the identity of a user and an identification of a domain name to be associated with the certificate; Identifying a first certificate authority selection policy applicable to the first request, wherein the first certificate authority selection policy includes a certificate authority selection rule; Evaluating the certificate authority selection rule to identify a certificate authority for generating the certificate, wherein the certificate authority selection rule associates at least a portion of the domain name with the certificate authority; Sending a second request to generate the certificate to the certificate authority; And Returning, from the certificate authority to the electronic device, the certificate or an identification of the certificate.
5. The computer-implemented method according to claim 4, wherein the first request does not include an identification of any certificate authority.
6. The computer-implemented method according to claim 4, further comprising: Before evaluating the certificate authority selection rule: Identifying a second certificate authority selection policy applicable to the first request; And Determining that the second certificate authority selection policy does not include a rule associated with the domain name.
7. The computer-implemented method according to claim 6, wherein the first certificate authority selection policy is associated with a group including the identity of the user, and the second certificate authority selection policy is associated with the identity of the user.
8. The computer-implemented method according to claim 4, further comprising: receiving, by the certificate management service, a third request to create the first certificate authority selection policy, wherein the third request includes (a) an association of at least a portion of the domain name with the certificate authority, and (b) a policy applicability that associates the first certificate authority selection policy with at least one of: (i) the identity of the user, (ii) a role associated with the identity of the user, or (iii) a group including the identity of the user; and storing the first certificate authority selection policy in a data repository.
9. The computer-implemented method according to claim 8, wherein the policy applicability is stored in metadata associated with the first certificate authority selection policy.
10. The computer-implemented method according to claim 4, wherein the certificate authority is (a) a private certificate authority service configured for use by an administrator of an organization including the user, or (b) a public certificate authority, wherein the public certificate authority is a service of the cloud provider network or a third party.
11. The computer-implemented method according to claim 4, wherein the first certificate authority selection policy applies to the first request by at least one of: (a) the first certificate authority selection policy being associated with the identity of the user, (b) the first certificate authority selection policy being associated with a role associated with the identity of the user, (c) the first certificate authority selection policy being associated with a group including the identity of the user, or (d) the first certificate authority selection policy being a default policy.
12. The computer-implemented method according to claim 11, wherein the first certificate authority selection policy is associated with a geographic region, and wherein the first certificate authority selection policy also applies to the first request at least in part based on the first request being received by the certificate management service in the geographic region.
13. The computer-implemented method according to claim 4, wherein the certificate authority is one of a plurality of certificate authorities available to the user.
14. A system, comprising: a first one or more electronic devices for implementing a data storage service of a cloud provider network, the data storage service including instructions that, when executed, cause the data storage service to store certificate authority selection policy data; and a second one or more electronic devices for implementing the certificate management service of the cloud provider network, the certificate management service including instructions that, when executed, cause the certificate management service to perform the following operations: receiving, from a third electronic device, a first request to generate a certificate, wherein the first request includes an indication of the identity of a user and an identification of a domain name to be associated with the certificate; Identify a first certificate authority selection policy that applies to the first request and is in the certificate authority selection policy data, where the first certificate authority selection policy includes a certificate authority selection rule; Evaluate the certificate authority selection rule to identify a certificate authority for generating the certificate, where the certificate authority selection rule associates at least a portion of the domain name with the certificate authority; Send a second request to the certificate authority to generate the certificate; And Return the certificate or an identifier of the certificate from the certificate authority to the third electronic device.
15. The system of claim 14, wherein the first request does not include an identification of any certificate authority.
16. The system of claim 14, the certificate management service including additional instructions that, when executed, cause the certificate management service to perform the following: Before evaluating the certificate authority selection rule: Identify a second certificate authority selection policy that applies to the first request; and Determine that the second certificate authority selection policy does not include a rule associated with the domain name.
17. The system of claim 16, wherein the first certificate authority selection policy is associated with a group including the identity of the user, and the second certificate authority selection policy is associated with the identity of the user.
18. The system of claim 14, the certificate management service including additional instructions that, when executed, cause the certificate management service to perform the following: Receive a third request to create the first certificate authority selection policy, where the third request includes (a) an association of at least a portion of the domain name with the certificate authority, and (b) a policy applicability that associates the first certificate authority selection policy with at least one of: (i) the identity of the user, (ii) a role associated with the identity of the user, or (iii) a group including the identity of the user; and Store the first certificate authority selection policy in the certificate authority selection policy data.
19. The system of claim 18, wherein the policy applicability is stored as metadata in the certificate authority selection policy data and is associated with the first certificate authority selection policy.
20. The system of claim 14, wherein the certificate authority is (a) a private certificate authority service configured to be used by an administrator of an organization including the user, or (b) a public certificate authority, where the public certificate authority is a service of the cloud provider network or a third party.
Citation Information
Patent Citations
Digital certificate management method and device based on multiple CAs, equipment and storage medium
CN110932861A
Digital security certificate selection and distribution
US20180062855A1